diff options
| author | Johan Hovold <johan@kernel.org> | 2017-03-06 17:36:40 +0100 |
|---|---|---|
| committer | Moyster <oysterized@gmail.com> | 2017-06-17 15:53:18 +0200 |
| commit | 8a1258c9a0dd4bac3a9397fa4f14bb6c10f645e8 (patch) | |
| tree | f5b89462486c6f279823f6f9eec6a0317c90178f /include/linux | |
| parent | ed0f1fa2d2b325e61c2971f7f8c6bf028fe862a6 (diff) | |
USB: serial: io_ti: fix information leak in completion handler
commit 654b404f2a222f918af9b0cd18ad469d0c941a8e upstream.
Add missing sanity check to the bulk-in completion handler to avoid an
integer underflow that can be triggered by a malicious device.
This avoids leaking 128 kB of memory content from after the URB transfer
buffer to user space.
Fixes: 8c209e6782ca ("USB: make actual_length in struct urb field u32")
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
Diffstat (limited to 'include/linux')
0 files changed, 0 insertions, 0 deletions
